argocd was originally helm-installed by hand before ArgoCD existed to
manage it; client-side 3-way merge apply can't prune fields it never
saw in a last-applied-configuration, so a later chart bump left a stale
args on repo-server's copyutil init container (old shell-string command
lingering alongside the new plain cp command) -> cp got 4 args instead
of 3 -> 'No such file or directory' -> CrashLoopBackOff -> Degraded.
Same bug class as envoy-gateway (020b248). ServerSideApply=true tracks
field ownership properly and prunes the stray field on next sync.
Convention: only the root app-of-apps (bootstrap) auto-syncs so it picks up
new/changed child Application definitions from Git. Every leaf service app
(metallb, metallb-config, envoy-gateway, envoy-gateway-config, nfs-provisioner)
now requires an explicit manual Sync — matches the existing argocd (self-manage)
and ignis convention.
Gateway API CRDs (httproutes, envoyproxies) have schemas large enough that
client-side apply's last-applied-configuration annotation exceeds the
262144-byte annotation limit. SSA skips that annotation entirely.
ArgoCD only builds a helm-pull command for oci:// sources when the repo is
registered with enableOCI: true; otherwise it falls back to classic --repo
handling, which errors on an oci:// URL. Registered via configs.repositories
in argocd's own values.yaml (Git-managed), Application source updated to
the bare host/path form ArgoCD expects for OCI repos.
Prevents perpetual OutOfSync on bgppeers.metallb.io and other metallb CRDs caused by apiserver-populated .status fields not present in the Helm chart source.